IT AUDITS IT audits: pemeriksaan terhadap proses atau data yang melekat dengan teknologi informasi. Berkaitan dengan internal, external, dan fraud audits.

Slides:



Advertisements
Presentasi serupa
Audit Sistem Informasi
Advertisements

Audit Wikipedia (id)‏ Audit atau pemeriksaan dalam arti luas bermakna evaluasi terhadap suatu organisasi, sistem, proses, atau produk. Audit dilaksanakan.
Audit Sistem Informasi
Sejarah & Pemahaman Audit Sistem/Teknologi Informasi
Auditing Computer-Based Information Systems
Memahami Audit Sistem/Teknologi Informasi
Audit Berbantuan Komputer
AUDIT SISTEM INFORMASI
Panduan Audit Sistem Informasi
Panduan Audit Sistem Informasi
Internal, Operational, and Governmental Auditing
Chapter 1: Auditing, Assurance, and Internal Control
SEJARAH DAN PEMAHAMAN AUDIT SISTEM/TEKNOLOGI INFORMASI
Electronic Data Processing
Control Objectives for Information and related Technology
Chapter 1: Auditing, Assurance, and Internal Control
Bab 1: Audit, Assurance, dan Pengendalian Internal
TEORI ORGANISASI DAN MANAJEMEN PENGETAHUAN
Dasar-dasar Audit Sistem Informasi
AUDIT SISTEM INFORMASI
Pengenalan Audit dan Audit SI/TI
Perkembangan Teknologi Alat bantu bekerja manual (dengan kertas, pensil, dan sebagainya) Alat bantu mekanis, elektro mekanis, dan Unit Record System Sudah.
Standar Pekerjaan Lapangan: Audit ats Cash
Audit Sistem Informasi Ujian Akhir 1 September 2008.
Electronic Data Processing
Computer Fraud Pertemuan XV Matakuliah: F0184/Audit atas Kecurangan Tahun: 2007.
The Demand for Audit and Other Assurance Services
1 INTRODUCTION Pertemuan 1 s.d 2 Matakuliah: A0554/Analisa dan Perancangan Sistem Informasi Akuntansi Tahun: 2006.
Audit & Kontrol TI Catatan: diolah dari berbagai sumber
BAB I Overview of Information System Auditing
Auditing, Assurance, and Internal Control
AUDIT SISTEM INFORMASI DAN PROSEDUR
Control Objectives for Information and related Technology
Pengantar Audit Sistem Informasi
OVERVIEW AUDIT SISTEM/TEKNOLOGI INFORMASI
AUDITING 1 Minggu ke-1 Widaryanti, SE, Akt Program Studi Akuntansi
Pert. 16. Menyimak lingkungan IS/IT saat ini
AUDIT SISTEM INFORMASI DAN PROSEDUR
UNIVERSITAS MERCU BUANA YOGYAKARTA 2016
Pengawasan Keuangan Daerah
AKUNTANSI PAJAK EDISI 6 WALUYO
OHS MANAGEMENT SYSTEM HENDRA.
Kontrol dan Audit Sistem Informasi
Audit Sistem Informasi
Company Owners and Lenders Company Managers
Internal Control Concepts
Penyusunan Blueprint TI untuk Perguruan Tinggi, by
Audit Sistem Informasi
Audit Teknologi sistem Informasi
Kertas kerja pemeriksaan akuntansi Dr Rilla Gantino, SE., AK., MM
Control Objectives for Information and related Technology (COBIT)
OVERVIEW AUDIT SISTEM INFORMASI
AUDIT SISTEM INFORMASI
Audit Teknologi Informasi Pertemuan 11
Organizational Environment Analysis
CobiT Control Objectives for Information and Related Technology
Penyusunan Blueprint TI untuk Perguruan Tinggi, by
ETIKA PROFESI Sesi 7.
KONSEP DASAR MELAKUKAN AUDIT SISTEM INFORMASI
KONSEP AUDIT SISTEM INFORMASI
Chapter 1: The Study of Accounting Information Systems
AUDIT SISTEM INFORMASI
AUDIT BERBANTUAN KOMPUTER
E-AUDIT KONSEP DASAR AUDIT.
Sistem informasi manajemen
Referensi Audit Sistem&Teknologi Informasi (Riyanarto Sarno) Strategi Sukses Bisnis dengan Teknologi Informasi (Riyanarto Sarno) Sistem Manajemen Keamanan.
Penyusunan Blueprint TI untuk Perguruan Tinggi, by
Kertas Kerja Pemeriksaan (Working Paper)
 Audit Sistem&Teknologi Informasi › (Riyanarto Sarno)  Strategi Sukses Bisnis dengan Teknologi Informasi › (Riyanarto Sarno)  Sistem Manajemen Keamanan.
Pertemuan 6 Audit Teknologi Informasi Kel 4 : - Aditya pratama.
Transcript presentasi:

IT AUDITS IT audits: pemeriksaan terhadap proses atau data yang melekat dengan teknologi informasi. Berkaitan dengan internal, external, dan fraud audits Jangkauan pemeriksaan IT semakin meningkat Teknik Audit Berbantuan Komputer (TABK)  CAATTs (Computer Assisted Audit Tools and Techniques)  audit through computer IT governance as part of corporate governance Sertifikasi  CISA (Certified Information Systems Auditor) Standar, pedoman dan sertifikasi dikelola oleh: ISACA (Information Systems Audit and Control Association)

Audit Around The Computer Seperti audit manual Hanya memeriksa input dan output saja, tanpa pemeriksaan lebih dalam terhadap penggunaan program. Jika input dan output benar  dianggap benar Dilakukan jika sebagian besar pengolahan data masih manual dan penggunaan komputer hanya ut beberapa bagian saja

Audit With The Computer Selain input dan output juga diperiksa proses pada komputer, dapat digunakan file-file transaksi yang berkaitan

Audit Through The Computer Melaksanakan pekerjaan audit dengan bantuan komputer

Lecture notes IS Auditing IT AUDITS IT audits (Hall, 2005) : Focus on the computer-based aspects of an organization’s information system Assess the proper implementation, operation, and control of computer resources Haryono, MCom, Akt. 3

Information System Auditing (Weber,1999) “IS Auditing is the process of collecting and evaluating evidence to determine whether a computer system safeguards assets, maintains data integrity, allows organizational goals to be achieved effectively, and uses resources efficiently”

The Work of an IT Auditor Evaluating controls over specific applications Providing assurance over specific processes Providing third-party assurance Penetration testing Supporting the financial audit Searching for IT-based fraud (Hunton, 2004)

What is an IT Audit? … most accounting transactions to be in electronic form without any paper documentation because electronic storage is more efficient. … These technologies greatly change the nature of audits, which have so long relied on paper documents.

IT Audit? Proses pengumpulan dan evaluasi fakta/bukti untuk menentukan apakah sistem (terkomputerisasi): Menjaga aset Memelihara integritas data Memampukan komunikasi & akses informasi Mencapai tujuan operasional secara efektif Mengkonsumsi sumber daya secara efisien

Lecture notes IS Auditing Issues in IS Auditing Why we are concerned about control and audit of computer systems Nature & types of management and application controls and their relative strengths and limitations Types of evidence collection techniques available Types of evidence evaluation techniques available How to do an IS audit and how to manage its Haryono, MCom, Akt.

Need for Control & Audit of Computer Systems

OBJECTIVES OF IS AUDITING Improved asset safeguarding Improved system effectiveness Improved system efficiency IS Auditing Improved data integrity

Changes to Evidence Collection New internal control technology needed Greater number and diversity of internal controls Internal controls are more critical New evidence collection technologies needed Greater number and diversity of evidence collection techniques

Changes to Evidence Evaluation Computer errors tend to be deterministic rather than stochastic  computer – always executes incorrectly Overall evaluation of the evidence collected is more difficult to undertake

Effects of Other Disciplines on IS Auditing Traditional Auditing Computer Science Behavioral Science IS AUDITING IS/IT Security Management IS Management

CISA Examination Content Areas

Impact IT on Audit Profession Education programs needed Quality publications needed in IT area IT Chapter needed New methods and fresh approaches required Auditing in real time

Substantive Testing Phase Phases of an IS audit Review of Organization’s Policies, Practices & structure Plan test of controls and Substantive Testing Procedures Audit Planning Phase Review General and Application controls Test of Controls Phase Substantive Testing Phase Perform Tests of Controls Perform Substantive Tests Evaluate Test Results Evaluate results and Issue Auditor’s report Determine degree of Reliance on controls Audit Report

THE IT ENVIRONMENT Selalu diperlukan sistem pengendalian internal yang efektif  pemanfaatan teknologi informasi. Lingkungan dengan IT menciptakan ‘kerumitan’ baru dari sistem ‘kertas’ sebelumnya: Data digital menjadi utama pentingnya akses dan hubungan dalam jaringan Meningkatnya cara kecurangan atau kejahatan baru yang mungkin sulit dideteksi. (baik manajemen ataupun dari pihak luar)

THE IT ENVIRONMENT Audit planning Tests of controls Substantive tests CAATT (Computer Assisted Audit Tools and Techniques)

INTERNAL CONTROL is … policies, practices, procedures … designed to … safeguard assets ensure accuracy and reliability promote efficiency measure compliance with policies